Johannesburg

Wednesday

Sunny. Pleasantly warm.

12°C
27°C

7 day forecasts

Risks of using web cafes

2003-07-23 10:12

New York - For more than a year, unbeknownst to people who used Iinternet terminals at Kinko's photocopying and printing stores in New York, Juju Jiang was recording what they typed, paying particular attention to their passwords.

Jiang had secretly installed, in at least 14 Kinko's stores, software that logs individual keystrokes. He captured more than 450 user names and passwords, using them to access and even open bank accounts online.

The case, which led to a guilty plea earlier this month after Jiang was caught, highlights the risks and dangers of using public internet terminals at cybercafes, libraries, airports and other establishments.

"Use common sense when using any public terminal," warned Neel Mehta, research engineer at Internet Security Systems Inclusion.

"For most day-to-day stuff like surfing the web, you're probably all right, but for anything sensitive you should think twice."

Jiang was caught when, according to court records, he used one of the stolen passwords to access a computer with GoToMyPC software, which lets individuals remotely access their own computers from elsewhere.

The GoToMyPC subscriber was home at the time and suddenly saw the cursor on his computer move around the screen and files open as if by themselves. He then saw an account being opened in his name at an online payment transfer service.

Jiang, who is awaiting sentencing, admitted installing Invisible KeyLogger Stealth software at Kinko's as early as February 14, 2001.

The software is one of several keystroke loggers available for businesses and parents to monitor their employees and children. The government even installed one such program to capture a password that the son of jailed mob boss Nicodemo "Little Nicky" Scarfo used to access files on his computer.

Earlier this year, a former Boston College student pleaded guilty to using similar software on more than 100 computers around campus to collect passwords and other data to create a campus ID card for making purchases and entering buildings illegally, authorities say.

Web users urged to be careful

Mehta said that while millions of individuals use public terminals without trouble, they should be cautious.

"When you sit down at an internet cafe, ask the owner or operator about the security measures in place," he said. "If they don't know or don't have anything in place, you could consider going somewhere else."

Encrypting e-mail and web sessions does nothing to combat keystroke loggers, which capture data before the scrambling occurs. But encryption can guard against network sniffers - software that can monitor e-mail messages, passwords and other traffic while it is in transit.

Data cookies also contribute to the risk of identity theft. Cookies are files that help websites remember who you are so you won't have to keep logging on to a site. But unless you remember to log out, these files could let the next person using the public terminal to surf the web as you.

Furthermore, browsers typically record recent websites visited so users won't have to retype addresses. But such addresses often have usernames and other sensitive information embedded.

Secure public terminals should by default have provisions for automatically flushing cookies and web addresses when a customer leaves, internet security experts say.

Kinko's spokesperson Maggie Thill said the company takes security seriously, and believes it has "succeeded in making a similar attack extremely difficult in the future".

She would not provide details, saying that to do so could make systems less secure.

Nonetheless, Thill said customers have a responsibility to "protect their information as they would a credit card slip." She said the company is trying to educate them through signs and other warnings.

At one Kinko's that authorities said Jiang targeted, a sign attached to individual $18-per-hour stations warns: "Be Safe. Protect Your Personal Information."

Richard M Smith, a security consultant in Cambridge, Massachusetts, said customers could also use certain techniques to foil keystroke loggers.

When typing in sensitive information, for instance, he suggests cutting and pasting individual characters from elsewhere to form the password.

No keys depressed, no characters logged. - Sapa-AP

- SAPA

inside news24

Latest comment in Sci-Tech

Homer says... MMMMM! BEER! Read the article...

Weather
Traffic
Lottery
Cpt: 19-24°C More sun than clouds. Mild. Pta: 15-29°C Sunny. Pleasantly warm.
Jhb: 12-27°C Sunny. Pleasantly warm. Bloem: 18-31°C More sun than clouds. Pleasantly warm.
Dbn: 24-33°C Sunny. Warm. PE: 21-26°C Afternoon clouds. Mild.
7 day forecasts...

Jobs - Find your dream job

Teller

Gauteng
First National Bank

Financial Manager (Only South African Citizens )

Gauteng - Johannesburg
Network Finance Menlyn
R460,000-500,000 Per Annum Cost To Company

Financial Manager (Only South African Citizens )

Gauteng - Johannesburg
Network Finance Menlyn

Cars - Search 1000's of new and used cars

AUDI

Audi R8 4.2 V8 R-Tronic
from R1 099 000.

TOYOTA

Yaris T1 1.0 3-dr AC
2008
R 105,990.00

AUDI

A4 Avant 1.9TDi Dsl 6-sp
2004
R 85,500.00

DAEWOO

Nubira II 1.6 SX
2002
R 59,900.00

Property - Find a new home

PARKVIEW

Single Residential R9,900,000

GILLITTS

Single Residential R4,995,000

CELTISDAL

Single Residential R1,950,000

Travel - Look, Book, Go!

Free Games - TOO MUCH NEWS? TAKE A BREAK!

Kalahari.net - shop online today

All Books on Sale!

2.3 million titles to choose from.

Sleek New iPod Range. Order Your's Now!

iPod nano 16GB - Black, Was R2,499.00 Now R2,299.00! Save R200!

All DVDs on Sale!

46 000 DVDs and Blu-Ray on sale now!

ALL Music on Sale

100s of festive new releases now in stock! Now, Bump 25, Bon Jovi & more!

1000s of Toys on Sale

Lots of Toys, free gift wrap, lowest prices on Lego Mindstorm, Ben 10, Hannah Montana & more!

Hot Deal of the Day!

Valentine's Day Flowers & Hampers

12 Red Roses in Cello - Now R439.00

Hurry last day to order a wide selection of Valentine’s roses and Flowers, Hampers, Jewellery & so much more.

Visit www.kalahari.net for millions of books, music, DVDs, games & more!